---
title: "ShinyHunters Pivots to Subdomain Phishing & Vishing"
metaTitle: "ShinyHunters Pivots to Subdomain Vishing"
description: "It still kicks off with a vishing attack, but ShinyHunters is switching from easily detected lookalike domains to bogus subdomains that can fly under the radar."
slug: shinyhunters-subdomains-vishing
date: "2026-02-27T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/subdomain-vishing.webp"
  alt: Closeup on a mysterious person with a shadowed face on a call with a red handset.
sourcePublisher:
  name: SecurityBrief UK
  url: "https://securitybrief.co.uk/"
sourceArticle:
  url: "https://securitybrief.co.uk/story/shinyhunters-pivots-to-subdomain-phishing-vishing"
tags: ["Vishing", "Tech Support Scam", "Identity Compromise"]
status: published
---

ReliaQuest warns that the extortion group ShinyHunters appears to be shifting its social engineering playbook toward branded subdomain impersonation, paired with phone-led phishing that targets single sign-on users on mobile devices.

The shift moves away from newly registered lookalike domains. Instead, attackers use generic registered domains and place the victim organisation's branding in the subdomain-a structure that can evade controls designed to flag suspicious or newly created domains.

ShinyHunters is a financially motivated group linked to data theft and extortion. Recent incidents suggest a focus on identity compromise and access to software-as-a-service platforms, rather than deploying malware inside corporate networks...
